There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.
References
Configurations
History
16 Apr 2025, 15:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Nacl122/CVEReport/blob/main/CVE-2023-42286/CVE-2023-42286.md - Exploit | |
First Time |
Eyoucms
Eyoucms eyoucms |
|
CPE | cpe:2.3:a:eyoucms:eyoucms:1.6.4:*:*:*:*:*:*:* |
13 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
21 Nov 2024, 08:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Nacl122/CVEReport/blob/main/CVE-2023-42286/CVE-2023-42286.md - |
12 Nov 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 |
14 Mar 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-14 22:15
Updated : 2025-04-16 15:29
NVD link : CVE-2023-42286
Mitre link : CVE-2023-42286
CVE.ORG link : CVE-2023-42286
JSON object : View
Products Affected
eyoucms
- eyoucms
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type